CVE-2025-55242Medium· 6.5▾ SunlitExposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.
xbox_gaming_servicesRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58611High· 7.8Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVE-2024-37325High· 8.1Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
CVE-2024-35263Medium· 5.7Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-30096Medium· 5.5Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header